SC-200 · Question #431
You have a Microsoft 365 subscription. The subscription contains 500 devices that are onboarded to Microsoft Defender for Endpoint. You have an Azure subscription that contains a Microsoft Sentinel…
The correct answer is C. a device group. To automatically remediate threats for a selected group of devices in Microsoft Defender for Endpoint, you should create a device group in the Microsoft Defender portal and set its Automation level to Full - remediate threats automatically. This configuration enables automated…
Question
You have a Microsoft 365 subscription. The subscription contains 500 devices that are onboarded to Microsoft Defender for Endpoint. You have an Azure subscription that contains a Microsoft Sentinel workspace. You need to run a pilot on 50 devices that will remediate threats automatically. The solution must meet the following requirements:
- Minimize the impact on devices that are excluded from the pilot.
- Minimize administrative effort.
What should you configure first?
Options
- Aa playbook
- Ban endpoint security policy
- Ca device group
- Dan automation rule
How the community answered
(34 responses)- A3% (1)
- B6% (2)
- C82% (28)
- D9% (3)
Explanation
To automatically remediate threats for a selected group of devices in Microsoft Defender for Endpoint, you should create a device group in the Microsoft Defender portal and set its Automation level to Full - remediate threats automatically. This configuration enables automated actions to be performed on entities considered malicious within that specific device group. https://learn.microsoft.com/en-us/defender-endpoint/configure-automated-investigations-
Community Discussion
No community discussion yet for this question.